When you type a question into ChatGPT. Then what? Is this private between you and the app? What if you type questionable content, ask how to hide money from the IRS, or how to fire your boss? Short answer: IRS is clean. Nothing gets reported.
Nothing goes to the police automatically. However, important internal controls can mean your chat is reported to someone.

This is important. The Chat App vendor has a privacy policy that controls what the vendor does by choice. It says nothing about what the vendor can be forced to do. OpenAI deletes your deleted chats in about 30 days. Anthropic keeps safety scores for up to seven years. Google keeps chats a human reviewed for three years, even after you delete them. None of those numbers matter once a court sends a request.
What AI Companies Actually Report
Every major AI company runs the same basic system. Software scans what you type. Most of what it catches goes nowhere. A small slice gets a human. A tiny slice leaves the building.
Tier 1: Reported to authorities
One category, and only one, is required by law. Child sexual abuse material. US companies must report it to the National Center for Missing and Exploited Children under 18 U.S.C. 2258A, and NCMEC passes cases to police.
This is not a gray area or a judgment call. Anthropic scans uploaded images against NCMEC’s known-image database automatically. A match gets reported with your account details. In the first half of 2026 it filed 15,079 reports. Most were automatic image matches. OpenAI reports all instances and bans the account.
Tier 2: Sent to a human reviewer
Some things get a person to look, and that person may call someone. Credible threats against a real, named person. Weapons capable of mass casualties. Attacks on power grids or water systems. Coordinated scam or influence operations. And any account that keeps violating the rules.
OpenAI routes threats against other people to specialized human review, and says cases involving an imminent threat of serious physical harm may go to law enforcement.
Tier 3: Refused and logged
Everything else. Malware. Exploit code. Drug synthesis. Weapons. Adult content. You get a refusal and a note on your file. Nobody calls anyone.
What moves something from tier 3 to tier 2 is usually not the request. It is doing it over and over.
You will not be told. No company says it notifies you when a human reads your chat. You find out only if you get a warning, a restriction, or a ban.
One thing the news gets wrong
Self-harm is not reported to police. You have probably read that it is. OpenAI says plainly that it refers threats against other people, and does not refer self-harm cases, on privacy grounds. What you get instead is crisis resources in the chat.
What “Private Mode” Actually Does
The big US AI companies all offer private chat. None of them make your chat private.
OpenAI’s Temporary Chat stays out of your history and out of training. It is still kept for up to 30 days. Anthropic’s Incognito chats work the same way, also 30 days, longer if flagged. Grok’s Private Chat deletes within 30 days. Google’s Temporary Chat holds 72 hours.
Your boss can still read it. You can be fired for it.
On work accounts, private chats are not private from your employer. Anthropic includes incognito chats in organization data exports and its Compliance API. OpenAI makes temporary chats available to Enterprise admins for 30 days, and says so plainly: that applies “regardless if a custom retention period is defined.”
Microsoft goes further. Its Purview tools let a compliance reviewer see the prompt text you typed, in full. Google’s Vault rules apply to Gemini chats “even if users start temporary chats or delete their conversations.”
Turning off training does not turn off review
Most people find the training toggle and assume they are done. They are not. Anthropic says that if safety classifiers flag a conversation, it may still be reviewed and used – whatever your setting says. OpenAI keeps temporary chats up to 30 days “for safety purposes.” Microsoft is blunt about it: “an opt-out of human review is not available.”
Deleting is not always deleting
Anthropic keeps flagged content for two years, and its trust and safety scores about you for seven. Google keeps chats a human reviewed for up to three years, and says they “are not deleted when you delete your activity.”
Delete removes it from your view. Sometimes that is all it does.

The Real Gap: Your Chat Left Your Computer
You already accept this next part. You know your Google searches can end up in court. People have been convicted on their search history.
That was never about Google. It was about the search leaving your machine. Once a query lands on someone else’s server, it becomes their record. And their records can be demanded.
Policy is not protection
A privacy policy tells you what a company chooses to do. It has nothing to say about what a company can be made to do. Those are separate questions, and only one of them is up to the company.
How the gap gets opened
From least effort to most:
- A freeze request. Police can tell a company to preserve your records for 90 days while they go look for grounds. No judge. No notice to you. Your data outlives the deletion policy.
- An emergency handover. Both Anthropic and OpenAI can release your data with no court order at all if they believe someone faces imminent physical harm or death. That is the company’s judgment call, not a judge’s.
- A subpoena for your account records. No judge required.
- A warrant for the actual words you typed.
- A gag order so the company cannot tell you any of this happened.
- A civil lawsuit. Divorce. A dispute with an employer. Same logs, no crime needed.
- Someone else’s lawsuit. In 2025 a court ordered OpenAI to preserve chat logs it would otherwise have deleted, in a copyright case no user was part of. Your delete setting lost to a stranger’s court filing.
So what about the IRS?
Nothing goes to the IRS on its own. There is no pipeline, no partnership, no automatic report. But the IRS can subpoena like anyone else. If you are already under investigation, your chats are reachable.
Your AI chat has no privilege
Talk to a lawyer and it is privileged. Talk to your accountant and there are protections. Talk to an AI and there is nothing. No confidentiality, no privilege, no professional shield.
If you are the professional, it cuts the other way. Under 26 U.S.C. 7216, a tax preparer who puts client-identifiable information into a public AI tool without consent faces civil and criminal penalties.
Using local AI is a privacy solution
Run the model on your own machine. A local AI, or local image and video generation on your own GPU, has no vendor, no server, and no log for anyone to subpoena.
Three Cases People Ask About
First, one distinction that clears up most confusion. There are two different things people mean by consent.
Subject consent is whether the real person in the image agreed. Depicted consent is whether the scene shows consent. Only the first one is a legal question. The second is a plot.
Undressing apps
Apps that strip clothes off a photo. Many are marketed openly by overseas firms. That marketing tells you nothing about your own exposure.
The TAKE IT DOWN Act makes it a crime to publish an intimate image of a real, identifiable adult without their consent. AI-made images count. So does a disclaimer saying it is fake – that is not a defense.
Two things people get wrong. The crime is publishing, not generating. And consent to be photographed is not consent to be published. Those are separate permissions.
If the person is a minor, none of this analysis matters. It is child sexual abuse material, whatever app made it, and it is still illegal when no real child exists.
Since May 2026 platforms also have 48 hours to remove this content once someone reports it. Penalties run past $53,000 per violation.
Real people in political content
The May law only covers intimate images. A political deepfake is not intimate, so that law does not touch it.
Other rules do. Many states now require a disclosure label on synthetic political content near an election. Defamation still applies. So does the right to control commercial use of your own face. Parody has real protection.
The line is simple. Non-intimate satire is mostly protected speech.
Fantasy and fetish content
All adults, invented characters, unusual scenarios, non-human or creature subjects. No real person exists, so nobody’s consent is missing. Nothing here is reportable.
What is left is obscenity law, which is decided by a local jury after the fact, not by a checklist you can follow in advance. Platform rules are far stricter and will stop you long before the law does.
One real trap. Youthful-appearing characters. Species, setting, and art style do not matter. If a character reads as a child, you are in the one category with mandatory reporting.

The Line Is Not Public Versus Private
Most people think the rule is about whether something is public. It is not. The rule is about whether the file moved.
Obscenity law is written around verbs like ship, transport, sell, and distribute. Possession is not on that list. The Supreme Court held in 1969 that what you keep privately at home is protected.
So the ladder looks like this.
- You make it and keep it. Obscenity law does not reach it. Child sexual abuse material still does – possession alone is the crime there.
- You send it to one person. That is distribution. A private message, an encrypted app, one trusted friend – none of that matters. The statute has no minimum audience.
- They post it. That is their problem, and yours too if you handed it over expecting that.
- You post it free. Platform rules bind you long before the law does, and they are much stricter.
- You sell it. Now payment processors are involved, and their rules are tighter than any statute.
Private possession is protected. But the minute you share to one other person, you have opened the door as a publisher.
Edge cases worth knowing
Cloud backup counts as moving it. Google Drive and Dropbox scan what you upload. Syncing a folder is transmission, even though it feels like storage.
Payment processors outrank the law. Visa and Mastercard rules end more creator accounts than any prosecutor ever has.
Your model has a license too. Plenty of checkpoints and LoRAs forbid adult output even where the law allows it.
A LoRA trained on a real person turns your “generic” AI face into an identifiable individual. You built the evidence into the model.
Age records. Federal recordkeeping rules cover human performers. Synthetic content has none. However, may you need to retain a record that your content is AI created.
Outside the US this all changes. The UK and EU have their own rules.
What the AI Companies Actually Do
They refuse things. They keep a log. They send a narrow slice to a human. They report one category to authorities because the law requires it. That is the whole job.
They are not watching for you. They are not calling the police about your prompts.
The odds of an AI company reporting you for anything other than child abuse material are close to zero.
The exposure was never the company’s intentions. It was the transmission. Your prompt left your computer, landed on a server, and became a business record belonging to someone else. Everything after that is out of your hands and out of theirs.
Anything you share – even with one person – can break laws you never read, in places you have never been. And anything you keep to yourself, on your own machine, is protected private possession.
The Short Version
- Reported to police: child sexual abuse material. That is the list.
- Not reported: self-harm, adult content, and almost everything else. You get a refusal or a ban.
- Nothing goes to the IRS, but the IRS can subpoena it like anyone.
- Private mode is not private. It hides the chat from you and keeps a copy for 30 days.
- Your employer can read work chats, private mode included.
- Delete does not always delete. Flagged content and human-reviewed chats are kept for years.
- No privilege. An AI is not your lawyer, your accountant, or your doctor.
- Police need very little to freeze your records, and no judge at all.
- Keeping it is legal. Sending it is the crime. One recipient is enough.
- Local generation is the only choice that changes your legal position.
Frequently Asked Questions
Are my AI conversations private?
No. Every prompt goes to a company server and becomes their record. Private from other users, yes. Private from the company, a court, or your employer, no.
Can ChatGPT report you to the police?
For child abuse material, yes, and it is required to. For a credible threat against a real person, possibly, after a human reviews it. For anything else, no. You get a refusal or a ban.
Is Claude incognito really incognito?
Not really. Incognito chats stay out of your history and out of training. Anthropic still keeps them 30 days, longer if flagged, and includes them in organization exports and its Compliance API. So your employer can see them.
Can AI chats be used against you in court?
Yes. They are stored records with no legal privilege. Prosecutors, opposing lawyers, and divorce attorneys can all reach them.
Does AI report self-harm to authorities?
No. This one is widely misreported. OpenAI refers threats against other people and says it does not refer self-harm cases, on privacy grounds. You get crisis resources in the chat instead.
Can police get my AI chat history?
Yes, and it takes less than you think. Account records need only a subpoena. The actual text needs a warrant. Freezing your data for 90 days needs no judge at all.
Does deleting an AI chat really delete it?
Usually within about 30 days. But flagged content sticks around for two years at Anthropic, safety scores for seven, and Google keeps human-reviewed chats three years even after you delete your activity.
Does turning off training make my chats private?
No. It stops your words from teaching the model. It does not stop safety review. Anthropic reviews flagged chats regardless of your setting, and Microsoft states that opting out of human review is not available.
Can my employer see my AI conversations?
On a work account, yes. Admins can export conversations at OpenAI and Anthropic, including private chats. Microsoft compliance tools show your prompt text in full. Google Vault rules survive both temporary chats and deletion.
Are ChatGPT chats privileged like a lawyer or accountant?
No. There is no confidentiality and no privilege. And if you are a tax professional, putting client information into a public AI tool without consent carries civil and criminal penalties.
Are Chinese AI apps safe to use?
Different question entirely. The issue is not what they report, it is where your data sits and what rights you have over it. Several store data inside China, and none of the eight we checked document a private chat mode. Germany’s regulator went furthest: Berlin’s data protection commissioner reported DeepSeek to Apple and Google for removal, on the finding that “Chinese authorities have extensive access rights to personal data within the sphere of influence of Chinese companies.” Details below.
Company by Company: Where to Check Yourself
These are published policies as of September 2026. They describe what each company says it does, not what it does in practice. Policies change, so check the date on the page when you read it.
OpenAI (ChatGPT)
- Retention: chats kept until you delete them, then gone within about 30 days.
- Private mode: Temporary Chat. Kept up to 30 days for safety.
- Training: on by default for consumers, off by default for business.
- Admin access: Compliance API includes temporary chats for 30 days.
- Reporting: all CSAM to NCMEC; threats to others to human review, self-harm not referred.
- Zero retention: API only, approval required.
Anthropic (Claude)
- Retention: 30 days normally. Five years if training is on, two years if flagged, seven years for safety scores.
- Private mode: Incognito chats. 30 days, and included in org exports.
- Training: your choice at signup. Safety review happens either way.
- Admin access: org data export, Team and Enterprise owners only.
- Government requests: valid legal process required, with an emergency exception.
- Reporting: automatic image hash matching; 15,079 NCMEC reports in H1 2026.
Google (Gemini)
- Retention: 18 months by default. Human-reviewed chats kept three years, even after you delete.
- Private mode: Temporary Chat, retained 72 hours.
- Human review: stated plainly on the same page, with a warning not to enter anything confidential.
- Work accounts: Vault rules apply even to temporary or deleted chats.
- Emergency disclosure: documented outside the privacy policy, in a transparency FAQ.
Microsoft (Copilot)
- Retention: 18 months.
- Human review: “an opt-out of human review is not available.”
- Training: opt-out for consumers, excluded for work accounts.
- Work accounts: compliance reviewers see your prompt text in full.
- NCMEC: named in the general privacy statement, not a Copilot page.
xAI (Grok)
- Retention: no fixed period published. Deleted chats and Private Chat removed within 30 days, with safety and legal exceptions.
- Storage: United States.
- Government requests: valid binding order required, minimum disclosure promised.
- Reporting: CSAM to NCMEC per the acceptable use policy.
- Note: your Grok activity on X may be shared back for training. The policy’s effective date is not stated.
Alibaba (Qwen, Wan)
- Storage: “Singapore and Mainland China”, with group companies in both given remote access.
- Retention: no period stated.
- Private mode: not documented.
- Training: on by default, no opt-out toggle documented; terms take a perpetual license to your name, image and likeness.
- Domestic version: a separate Shanghai entity, data kept in China and not transferred abroad.
ByteDance (Doubao, Dreamina, Seedance)
- Domestic Doubao: stored in China, training on by default with a settings opt-out, consent waived for national security and criminal investigation.
- International Dreamina: US, Singapore and Malaysia servers, no training opt-out in the document.
- Dola, the overseas Doubao: Singapore entity, opt-out available, not offered in the US.
- Seedance via BytePlus: policy text could not be retrieved.
MiniMax (Hailuo)
- Consumer: Singapore entity, no storage location stated, no retention period, training not addressed at all.
- API: US data center, but the policy carries PRC consent exceptions verbatim – national security, public interest, criminal investigation.
- Private mode: not mentioned.
- Domestic: stored in China, real-name phone registration required.
Kuaishou (Kling)
- International: Singapore servers, no retention period, no EU entity named.
- Training: on by default via the terms, opt-out by email.
- Faces: says it collects no face data, but does upload “feature points” and contour lines.
- Domestic: an explicit reporting duty. On finding illegal content it reports your account, timestamps, network addresses, hardware details and the content you typed. Consent not required.
Zhipu AI (GLM, Z.ai)
- International: a Singapore entity under Singapore law. No mention of China or PRC law anywhere.
- Training: on by default for individuals, off for API customers, per the terms.
- Private mode: not documented.
- Note: the Beijing parent was added to the US Entity List in January 2025. That is an export control, not a consumer ban.
- The domestic policy could not be retrieved.
DeepSeek
- Storage: “we directly collect, process and store your Personal Data in People’s Republic of China” – same for US and UK users.
- Retention: no period stated anywhere.
- Private mode: none. Confirmed absent.
- Reporting: the terms state that records of suspected illegal behavior are retained and reported to the authorities.
- Regulators: Italy blocked it in January 2025; Berlin reported it to Apple and Google in June 2025.
- US: banned on government devices in New York, Texas, Virginia and several federal agencies. The federal bill has not passed.
Moonshot AI (Kimi)
- Three entities with different answers. kimi.com is the Beijing entity, stored in China. kimi.ai is a Singapore company naming no country. The API stores in Singapore.
- Which one you get depends on the domain you type.
- Training: on by default at all three. Only the Chinese version documents an opt-out, and it requires emailing support and verifying your identity.
- Private mode: not documented anywhere.
Tencent (Hunyuan, Yuanbao)
- Yuanbao is China-only. Data collected in China stays in China, and the policy has no stated effective date.
- Training: reported to be off by default after a 2025 user backlash, but this is not stated in any policy clause we could read. Treat as unconfirmed.
- International access is via Tencent Cloud, which may store in mainland China and carries a PRC addendum.
- Private mode: not documented.
Two patterns across all eight Chinese vendors. None documents a private or incognito chat mode. And the domestic versions require real-name registration tied to government ID, so nothing there is anonymous by design.